CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorrent functions by tampering the affected flag value of the config file a...Show more |
1Phoenixcontact 29Fl Switch 3004t Fx Firmware Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 moreNov 21, 2024 May 6, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts. |
1Cisco 2Rv320 Dual Gigabit Wan Vpn Router Software Rv325 Dual Wan Gigabit Vpn Router FirmwareJun 17, 2026 May 3, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid u...Show more |
1Crestron 2Am 100 Firmware Am 101 FirmwareJun 17, 2026 Apr 30, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote,...Show more |
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password. |
Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to READ/WRITE Customer or Administrator data via a persistent HTTP GET Requ...Show more |
A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication v...Show more |
A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application server. |
4Canonical FedoraprojectFreeradius+1 more4Enterprise Linux FedoraFreeradius+1 moreJun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. |
A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based authentication via the Wallpaper Carousel application to obtain sensitive Clipboard data an...Show more |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local...Show more |
1Cisco 1Wireless Lan Controller Software Nov 21, 2024 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user ses...Show more |
Contao 4.7 allows Use of a Key Past its Expiration Date. |
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cry...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacke...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authenticatio...Show more |
2Fedoraproject W1.fi3Fedora HostapdWpa SupplicantJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE su...Show more |
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and kn...Show more |
OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the...Show more |